A companyβs application currently uses an IAM role that allows all access to all AWS services. A SysOps administrator must ensure that the companyβs IAM policies allow only the permissions that the application requires. How can the SysOps administrator create a policy to meet this requirement?
- ATurn on AWS CloudTrail. Generate a policy by using AWS Security Hub.
- BTurn on Amazon EventBridge (Amazon CloudWatch Events). Generate a policy by using AWS Identity and Access Management Access Analyzer.
- CUse the AWS CLI to run the get-generated-policy command in AWS Identity and Access Management Access Analyzer.
- DTurn on AWS CloudTrail. Generate a policy by using AWS Identity and Access Management Access Analyzer. (correct answer)
Reveal answer & explanationHide answer
The correct answer is D. Option D: Turn on AWS CloudTrail. Generate a policy by using AWS Identity and Access Management Access Analyzer.
Explanation
AWS CloudTrail records API activity for auditing and governance.